ietf-asrg
[Top] [All Lists]

Re: [Asrg] RMX breaks mailing lists

2003-03-06 09:06:50

On Thursday, March 6, 2003, at 10:34 AM, Liudvikas Bukys wrote:
I looked back over the archives at the whole RMX discussion,
and looked at the Designated Senders draft as well, and it
appears that nobody has mentioned the problem that it
EITHER:
        - breaks legitimate forwarding such as mailing lists
OR
        - can be trivially worked around by forging Received headers

(After all, I didn't receive Hadmut Danisch's note from his server,
I received it from my internal relay, which received it from
an ietf.org server.)

So in the DS model, you would configure your internal relay to do the DS test, which had a sender of <asrg-admin(_at_)ietf(_dot_)org>, and ask IETF "is 132.151.1.19 authorized to send mail for ietf.org?", get an assurance of trust, and move on.

You could then set up your final-MX to say "trust all mail from my internal relay, because it's already done those checks itself".

The received headers never come into play. It's strictly concerned sender-domain (from the envelope) and connecting IP.

D

_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg